codependix-export

Pass

Audited by Gen Agent Trust Hub on Sep 3, 2026

Risk Level: SAFENO_CODEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill consists entirely of Markdown documentation for the codependix command-line utility. It does not include any scripts, automated triggers, or remote code fetch patterns. It focuses on explaining CLI flags and configuration options.\n- [INDIRECT_PROMPT_INJECTION]: The documentation mentions reading exported graphs in Mermaid or JSON format. While reading external data is a potential attack surface for indirect prompt injection, the skill describes the use of explicit HTML boundary markers (e.g., codependix:start and codependix:end) to delimit generated content, which is a recommended practice to reduce the risk of the agent misinterpreting data as instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 3, 2026, 10:39 PM
Security Audit — agent-trust-hub — codependix-export